Vaultwarden contains an authorization flaw affecting versions prior to 1.35.3 that allows a regular member of an organization to retrieve all ciphers stored in that organization, even when the member does not have permission to access the corresponding collections. The issue is in the organization cipher details functionality exposed through the /ciphers/organization-details endpoint. That endpoint is reachable by any organization member and internally retrieves all organization ciphers through logic equivalent to Cipher::find_by_org, then returns them as organization-synced ciphers without enforcing collection-level access control. As a result, authorization is checked only at the organization membership level and not at the finer-grained collection permission boundary intended to restrict cipher visibility.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python proof-of-concept script (CVE-2026-26012.py), plus README and Apache-2.0 LICENSE. The script targets Vaultwarden CVE-2026-26012 (authenticated organization collection permissions bypass / cipher enumeration). It normalizes a user-supplied base URL (defaults to https if no scheme), validates the provided organization UUID format, and performs authenticated API requests using a Bearer token. Core capability: it calls the vulnerable organization cipher endpoint (documented in README as /api/ciphers/organization-details) to retrieve and export all cipherDetails for an organization, even those in collections the user should not have access to. It computes basic statistics over the returned dataset (counts by cipher type such as Login/Secure note/Card/Identity, deleted vs active, presence of attachments/TOTP/password/notes/reprompt, and collectionId aggregation). Optional capability (-c/--compare-collections): it also queries /api/collections and compares the set of collection IDs accessible to the user with the collectionIds referenced by ciphers returned from organization-details, printing discrepancies (collections present in org ciphers but not accessible, and accessible collections absent from returned ciphers). No RCE or persistence is implemented; the impact is authenticated information disclosure/authorization bypass validation and local JSON export.
Repository contains a two-phase Python proof-of-concept for CVE-2026-26012 (Vaultwarden <= 1.35.2), a broken access control issue allowing any organization member to enumerate all organization ciphers regardless of collection permissions, and then decrypt them client-side. Structure: - README.md: Explains the vulnerability, affected/fixed versions, and usage for both phases. - poc_cve_2026_26012.py (Phase 1): Authenticated enumeration/leak detection. It supports auth via Bearer token, session cookie, raw Cookie header, or password-grant login (PBKDF2 only; Argon2id login is explicitly not supported in this script). It queries /api/sync (legitimate view) and /api/ciphers/organization-details (vulnerable view), computes the difference as “leaked” ciphers, prints summaries, and can export full results to JSON. - poc_decrypt.py (Phase 2): Completes the impact by recovering the organization key and decrypting leaked ciphers. It implements Bitwarden/Vaultwarden EncString parsing and decryption routines (AES-CBC with optional HMAC verification; RSA OAEP handling for org key wrapping). It derives keys from the user’s email + master password locally (PBKDF2 or Argon2id if argon2-cffi is installed) and uses /api/sync profile data to obtain encrypted user/org key material. It then decrypts cipher fields and outputs decrypted secrets (passwords, TOTP seeds, card numbers) with optional JSON export. Main exploit capabilities: - Authenticated API abuse to bypass collection-level authorization and retrieve all organization ciphers. - Automated leak confirmation by comparing counts/IDs between /api/sync and /api/ciphers/organization-details. - Client-side cryptographic key derivation and decryption to turn leaked ciphertext into plaintext secrets, demonstrating confidentiality impact. This is not a framework module; it is standalone PoC code with operational decryption functionality (beyond mere detection), but payload customization is not a focus (no shell/RCE).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.